> Markdown version of [/jobs/ext/1424638-it-cybersecurity-specialist](https://www.wearedevelopers.com/jobs/ext/1424638-it-cybersecurity-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Cybersecurity Specialist - **Company:** Graham Technologies - **Location:** Fort Gregg-Adams, VA, United States - **Experience:** Expert - **Salary:** $115,000.0 - $135,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Software System Penetration Testing, Cloud Engineering, Code Review, Collaborative Software, CompTIA Security+, Cyber Security, Information Systems, Continuous Integration, Issue Tracking Systems, Microsoft Software, Smartsuite, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Privacy Controls, Information Security Management System, Software Security, SC Clearance, Information Technology, Devsecops, Servicenow, Plan of Action and Milestones, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** July 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d823d9ad2dce86c5 ## About the Role * Minimum five (5) years of professional cybersecurity experience. * Experience supporting RMF, security authorization, continuous monitoring, vulnerability management, or incident response activities. * Experience applying NIST SP 800-53 controls and maintaining cybersecurity documentation. * Experience supporting Federal information systems or regulated environments. Education * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related discipline. Clearance * Active Secret clearance. Certifications / Tools * Active CompTIA Security+ or higher * Experience with vulnerability scanners, SIEM platforms, GRC tools, ticketing systems, and Microsoft collaboration tools., * Experience securing cloud-native, ServiceNow, DevSecOps, or CI/CD environments. * Experience with supply-chain risk management, Zero Trust, penetration testing, or application security. Education * Master's degree in Cybersecurity, Information Assurance, or a related discipline. Certifications * CISSP, CASP+, CCSP, CISM, CySA+, or equivalent advanced certification. ## Description * Support the development, maintenance, and assessment of security authorization documentation, including the System Security Plan, security controls, assessment artifacts, and supporting evidence. * Apply the Risk Management Framework and applicable NIST security and privacy controls throughout the system lifecycle. * Coordinate continuous monitoring activities, vulnerability scanning, remediation tracking, and monthly Plan of Action and Milestones updates. * Develop and maintain access-control, role-based access, incident-response, contingency, and security operating procedures. * Analyze security findings, assess risk, recommend corrective actions, and verify remediation effectiveness. * Support security engineering reviews for cloud, platform, application, API, and DevSecOps implementations. * Coordinate incident triage, containment, investigation, documentation, and recovery activities. * Support static and dynamic application security testing, penetration-testing coordination, and secure-code review activities. * Maintain audit-ready cybersecurity documentation and respond to security assessments, reviews, and data calls. * Collaborate with system owners, developers, administrators, project managers, and Government cybersecurity stakeholders. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf)